Selecting exemptions to strong authentication requirements
Abstract
Disclosed are various embodiments for selecting an exemption to a strong authentication requirement. In one embodiment, an exemption selection engine receives a payment transaction for a user account using a payment instrument from a payment issuer. The exemption selection engine determines, for a plurality of different exemptions from an authentication challenge performed by the payment issuer, whether the payment transaction qualifies for respective ones of the plurality of different exemptions. The exemption selection engine then identifies a particular exemption for the payment transaction from a subset of the plurality of different exemptions for which the payment transaction qualifies based at least in part on respective success histories for respective ones of the subset of the plurality of different exemptions.
Claims
exact text as granted — not AI-modifiedTherefore, the following is claimed:
1 . A non-transitory computer-readable medium embodying a program executable in at least one computing device, wherein when executed the program causes the at least one computing device to at least:
determine a ranking of a plurality of different exemptions from an authentication challenge performed by a payment issuer based at least in part on a corresponding likelihood of success for respective ones of the plurality of different exemptions; receive a payment transaction for a user account using a payment instrument from the payment issuer; determine, for the plurality of different exemptions, whether the payment transaction qualifies for the respective ones of the plurality of different exemptions; identify a particular exemption for the payment transaction from a subset of the plurality of different exemptions for which the payment transaction qualifies that is most likely to avoid the authentication challenge performed by the payment issuer according to the ranking; submit the payment transaction for processing by the payment issuer with the particular exemption requested; determine that the particular exemption has been approved by the payment issuer; and refrain from redirecting a client device associated with the user account to the authentication challenge performed by the payment issuer.
2 . The non-transitory computer-readable medium of claim 1 , wherein the plurality of different exemptions include at least one of: a first exemption based at least in part on a user designating a payee entity associated with the payment transaction as a trusted beneficiary, a second exemption based at least in part on the payment transaction being a recurring payment transaction associated with the payment instrument, a third exemption based at least in part on the payment transaction being initiated by the payee entity, a fourth exemption based at least in part on a value of the payment transaction being below a value threshold, or a fifth exemption based at least in part on an authentication challenge being performed by the payee entity instead of the authentication challenge performed by the payment issuer.
3 . The non-transitory computer-readable medium of claim 1 , wherein when executed the program further causes the at least one computing device to at least perform an authentication challenge for a payee entity instead of the authentication challenge performed by the payment issuer.
4 . A system, comprising:
at least one computing device; and an exemption selection engine executable in the at least one computing device, wherein when executed the exemption selection engine causes the at least one computing device to at least:
receive a payment transaction for a user account using a payment instrument from a payment issuer;
determine, for a plurality of different exemptions from an authentication challenge performed by the payment issuer, whether the payment transaction qualifies for respective ones of the plurality of different exemptions; and
identify a particular exemption for the payment transaction from a subset of the plurality of different exemptions for which the payment transaction qualifies based at least in part on respective success histories for respective ones of the subset of the plurality of different exemptions.
5 . The system of claim 4 , wherein the particular exemption is identified based at least in part on a machine learning model trained according to the respective success histories.
6 . The system of claim 4 , wherein the exemption selection engine further causes the at least one computing device to at least generate the respective success histories and assign a ranking to the plurality of different exemptions based at least in part on the respective success histories prior to receiving the payment transaction.
7 . The system of claim 4 , further comprising a payment handling service executable in the at least one computing device, wherein when executed the payment handling service further causes the at least one computing device to at least submit the payment transaction for processing by the payment issuer without the authentication challenge performed by the payment issuer by applying the particular exemption.
8 . The system of claim 7 , wherein when executed the payment handling service further causes the at least one computing device to at least:
determine whether applying the particular exemption for the payment transaction is successful; and update the respective success history for the particular exemption.
9 . The system of claim 4 , further comprising a plurality of exemption plugins executable in the at least one computing device, wherein individual ones of the plurality of exemption plugins are configured to report whether a corresponding exemption is available for the payment transaction.
10 . The system of claim 9 , wherein the individual ones of the plurality of exemption plugins are further configured to generate respective data for requesting the corresponding exemption from the payment issuer.
11 . The system of claim 4 , wherein one of the plurality of different exemptions corresponds to an exemption based at least in part on a user designating a payee entity associated with the payment transaction as a trusted beneficiary.
12 . The system of claim 4 , wherein one of the plurality of different exemptions corresponds to an exemption based at least in part on the payment transaction being a recurring payment transaction associated with the payment instrument.
13 . The system of claim 4 , wherein one of the plurality of different exemptions corresponds to an exemption based at least in part on the payment transaction being initiated by a payee entity.
14 . The system of claim 4 , wherein one of the plurality of different exemptions corresponds to an exemption based at least in part on a value of the payment transaction being below a value threshold.
15 . The system of claim 4 , wherein one of the plurality of different exemptions corresponds to an exemption based at least in part on an authentication challenge being performed by a payee entity instead of the authentication challenge performed by the payment issuer.
16 . The system of claim 4 , wherein the payment transaction is received by the exemption selection engine from a third-party payee entity, and the exemption selection engine reports the particular exemption to the third-party payee entity.
17 . A method, comprising:
receiving, via at least one of one or more computing devices, a payment transaction for a user account using a payment instrument from a payment issuer; determining, via at least one of the one or more computing devices, for a plurality of different exemptions from an authentication challenge performed by the payment issuer, whether the payment transaction qualifies for respective ones of the plurality of different exemptions; identifying, via at least one of the one or more computing devices, a particular exemption for the payment transaction from a subset of the plurality of different exemptions for which the payment transaction qualifies that is most likely to avoid the authentication challenge performed by the payment issuer; and submitting, via at least one of the one or more computing devices, the payment transaction for processing by the payment issuer with the particular exemption requested.
18 . The method of claim 17 , further comprising:
determining, via at least one of the one or more computing devices, that the payment issuer has denied the particular exemption; and redirecting, via at least one of the one or more computing devices, a client device associated with the user account to the authentication challenge by the payment issuer.
19 . The method of claim 17 , further comprising:
determining, via at least one of the one or more computing devices, that the payment issuer has approved the particular exemption; and refraining from redirecting, via at least one of the one or more computing devices, a client device associated with the user account to the authentication challenge by the payment issuer.
20 . The method of claim 17 , further comprising generating, via at least one of the one or more computing devices, a ranking of the plurality of different exemptions for likelihood of success based at least in part on respective success histories of the plurality of different exemptions with the payment issuer.Join the waitlist — get patent alerts
Track US2021065170A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.